Researchers linked multiple generations of Turla malware—including Agent.BTZ, ComRAT, Uroburos/Snake, and TinyTurla—to a long-running cyber-espionage operation that continued to evolve its tooling while preserving technical ties to earlier campaigns. Newer ComRAT samples were identified alongside more than 70 previously unknown IP and DNS indicators, with the malware delivered through a fake WinRAR self-extracting installer, loading a proxy DLL (activeds.dll) and a main payload (stdole2.tlb) into explorer.exe. Analysts also documented overlaps between Agent.BTZ and later Turla tooling, including reused XOR keys, shared artifacts, and code similarities, reinforcing the view that older Pentagon-breach-era malware remained influential in Turla’s later implants.

TTPs, infrastructure, and targeting history in one profile.
18 events from the most recent confirmed update back to the earliest known activity.
Intezer reported finding about a dozen new Agent.BTZ/ComRAT samples and more than seventy previously unknown live IP and DNS indicators. The research said the infrastructure showed ongoing abuse of satellite Internet providers in Africa and the Middle East.
A 2022 analysis of TinyTurla described a 64-bit DLL installed as a Windows service named "Microsoft Windows Time," with configuration stored in the registry and HTTPS C2 using the victim MachineGuid in a "Title" header. The report documented 12 supported commands for process execution, file handling, and configuration changes.
A 2021 Securelist analysis highlighted technical overlaps between Agent.btz and Turla, including identical log-file names and the same XOR key, and noted Red October searched USB drives for Agent.btz artifacts. The article stopped short of concluding the malware families had the same developers.
Kaspersky published research in 2015 describing Turla's use of hijacked downstream satellite Internet links and packet spoofing to conceal command-and-control infrastructure. The report tied observed Turla-related domains and IPs to satellite providers in the Middle East and Africa.
The file names activeds.dll and stdole2.tlb were first used by Agent.BTZ in late 2014. Later Intezer research identified these names again in newer variants.
The analyzed ComRAT v3.25 dropper had a compilation date of 2014-02-06. G Data used this sample to document overlaps among ComRAT, Agent.BTZ, and Uroburos.
G Data analyzed ComRAT versions 3.25 and 3.26 and reported shared code, a historically reused XOR key, and shared C2 infrastructure with Uroburos and Agent.BTZ. The report also noted ComRAT v3.26 changed its keying and removed a prior installation-log artifact to hinder analysis.
Investigators first became aware of the targeted Turla campaign in March 2013 while analyzing a sophisticated rootkit they called the Sun rootkit. The article states the Sun rootkit and Uroburos were the same malware.
Agent.btz was detected 13,832 times across 107 countries in 2013 alone. The article also states infections steadily declined from 2011 through 2013 despite this broad global presence.
Turla samples dated 2013 to 2014 were found to contain the same XOR key used by Agent.btz for log encryption. This was one of the technical overlaps later cited between the malware families.
By 2011, a large number of Agent.btz modifications had been detected. The references also note Russia had the highest number of detections in 2011, beginning a multi-year trend.
Known Red October USB Stealer modules were created in 2010 and 2011. Later analysis found these modules searched USB drives for Agent.btz-related files such as thumb.dd and mssysmgr.ocx.
The 2008 Agent.btz incident led to Operation Buckshot Yankee to clean U.S. military networks. This was the operational response to the worm's spread in military environments.
Agent.btz infected local networks of U.S. military operations in the Middle East in 2008 and became historically associated with the Pentagon breach. The incident established Agent.btz as a major early espionage malware case.
The XOR key later noted as shared between Agent.btz and Turla log encryption was discovered and published in 2008. This became an important technical overlap cited in later analysis.
A Turla backdoor identified as Agent.DNE had a compilation timestamp of 2007-11-22 and contained a hardcoded satellite-provider IP address. Kaspersky cited this as evidence Turla had been using satellite-based Internet links for C2 since 2007.
Researchers believe the initial Agent.btz variants were created in 2007. This predates the better-known 2008 military-network infections.
Turla was described as impacting government, embassy, military, education, and research organizations since 2004. This marks the earliest stated start of the group's activity in the provided references.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 198 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
intezer.com
Open sourcecybergeeks.tech
Open sourcesecurelist.com
Open sourcegdatasoftware.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.